cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
389
Views
0
Helpful
1
Replies

Posture on Machine Behind IP Phone with power adapter

Neelesh Marathe
Cisco Employee
Cisco Employee

Team,

 

I am working with one of the Banks in India. They are running dot1x and posture on windows endpoints and IP Phones are getting authenticated using MAB. Edge switches are not PoE and IP Phones get power through power adapter. We are facing challenge in scenario where system is connected behind IP Phone. 

 

When I remove machine cable from IP Phone, posture works fine and machine becomes compliant.

 

When I remove switch cable from IP Phone, IP phone network gets disconnected however IP Phone stays powered on as it is using external power. Machine network stays also connected and posture status on module does not get changed. Now when I plug the switch cable again in IP Phone, both phone and  Machine get authenticated however posture module will not able to detect the network change. I tried enabling VLAN detection, periodic probing however it did not work

 

We are using following AnyConnect 4.4.04030 and compliance module 3611098.2

 

I am seeking your guidance for next course of action

 

Thanks,

Neelesh Marathe

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

If the PC not performing DOT1X after restoring the connectivity between the switch and the IP phone, then the user would have to un-plug and re-plug-in the cable of the PC. If DOT1X happens, then try Posture Enhancements in ISE 2.4 and AC 4.6.

View solution in original post

1 Reply 1

hslai
Cisco Employee
Cisco Employee

If the PC not performing DOT1X after restoring the connectivity between the switch and the IP phone, then the user would have to un-plug and re-plug-in the cable of the PC. If DOT1X happens, then try Posture Enhancements in ISE 2.4 and AC 4.6.